{"id":"JLSEC-2026-1248","summary":"A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL...","details":"A flaw was found in GLib. The D-Bus client-side implementation of the `DBUS_COOKIE_SHA1` SASL authentication mechanism does not validate the `cookie_context` parameter received from the server. A malicious D-Bus server can supply a `cookie_context` containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.","modified":"2026-08-11T14:14:15.555363690Z","published":"2026-08-11T13:55:26.657Z","upstream":["CVE-2026-58015","EUVD-2026-40318","GHSA-hmpf-72wc-2r6x"],"database_specific":{"sources":[{"html_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58015","database_specific":{"status":"Modified"},"id":"CVE-2026-58015","imported":"2026-08-11T06:49:24.148Z","modified":"2026-08-03T06:16:39.077Z","published":"2026-06-30T13:19:17.707Z","url":"https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-58015"},{"published":"2026-06-30T15:30:45Z","url":"https://api.github.com/advisories/GHSA-hmpf-72wc-2r6x","html_url":"https://github.com/advisories/GHSA-hmpf-72wc-2r6x","id":"GHSA-hmpf-72wc-2r6x","imported":"2026-08-11T06:49:25.756Z","modified":"2026-08-03T06:32:44Z"},{"modified":"2026-08-03T04:04:47Z","published":"2026-06-30T13:02:45Z","url":"https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-40318","html_url":"https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-40318","id":"EUVD-2026-40318","imported":"2026-08-11T06:49:24.330Z"}],"license":"CC-BY-4.0"},"references":[{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:49512"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-58015"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2492256"},{"type":"WEB","url":"https://github.com/advisories/GHSA-hmpf-72wc-2r6x"},{"type":"WEB","url":"https://gitlab.gnome.org/GNOME/glib/-/issues/3931"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58015"}],"affected":[{"package":{"name":"Glib_jll","ecosystem":"Julia","purl":"pkg:julia/Glib_jll?uuid=7746bdde-850d-59dc-9ae8-88ece973131d"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.88.3+0"}]}],"database_specific":{"source":"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1248.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}